SonicJobs Logo
Left arrow iconBack to search

Senior Infrastructure Engineer

Portal Space Systems
Posted a day ago, valid for 25 days
Location

Bothell, WA, US

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

About Portal

Portal Space Systems is on a mission to expand humanity’s freedom of movement in space. We’re building the spacecraft that makes that mission possible. From our Bothell, WA headquarters, we design vehicles with the maneuverability, resilience, and adaptability needed for the next era of orbital operations. Every system we build is in service of a simple idea: space should be more accessible, responsive, and capable. Joining Portal means stepping into a team that believes in bold engineering, fast iteration, and the power of small groups to change what’s possible. If you want your work to directly shape the future of in-space mobility, join us.

Position Summary

The Senior Infrastructure Engineer owns the architecture and engineering of Portal’s infrastructure, using Azure to its full potential rather than treating the cloud as a place to park virtual machines. The role is responsible for identifying where managed services, automation, and cloud-native patterns can replace manually maintained infrastructure; maintaining a simple, single-site on-premises VMware footprint; engineering backup and disaster recovery; and serving as the technical escalation point and including on-call for critical incidents, for infrastructure issues beyond the scope of the service desk. This position works closely with the service desk and the engineering teams, and reports directly to the Director of IT, building infrastructure that scales as Portal plans for rapid growth.

Responsibilities

Cloud-Native Infrastructure Architecture & Engineering

  • Design cloud-native solutions on Azure: leveraging managed services, PaaS, serverless, and platform-native tooling, rather than defaulting to lift-and-shift VM replication of on-premises patterns
  • Continuously evaluate infrastructure for modernization opportunities, replacing manually maintained servers with managed services where they reduce operational burden and improve resilience
  • Maintain Portal’s on-premises footprint on a VMware cluster, running basic networking and VMs, keeping it simple and current rather
  • Design infrastructure that scales cost-effectively as Portal rapidly grows
  • Stay technically ready to extend infrastructure to on-site/edge processing if the business requires it, without prioritizing that buildout today

Network, Identity & M365 Platform Ownership

  • Own Portal’s network infrastructure (Fortinet stack) across on-premises and Azure Government
  • Serve as the primary in-house owner of Microsoft Entra ID and the broader Microsoft 365/Azure Government tenant, working alongside M365 and MSP support to demonstrate direct ownership of these systems
  • Design and maintain identity, conditional access, and network segmentation in support of least-privilege principles and the compliance framework (CMMC Level 2, DFARS, ITAR)

Backup, Disaster Recovery & Reliability

  • Own backup strategy and execution using Veeam across on-premises and cloud workloads
  • Engineer and maintain cloud-based disaster recovery for Portal’s on-premises VMware environment, treating DR as a continuously tested capability rather than a one-time project
  • Participate in an on-call to respond to critical infrastructure incidents outside business hours
  • Treat compute as disposable rather than precious: build with infrastructure as code so environments can be rebuilt on demand instead of hand-nursed back to health

Service Desk Escalation & Internal Customer Experience

  • Serve as the escalation point for the MSP-staffed tier-1 service desk on infrastructure issues (servers, network, Entra ID/M365) beyond their knowledge or authority
  • Treat repeat escalations as a design problem: fix the underlying cause so the same issue doesn’t come back, rather than resolving it ticket by ticket
  • Deliver responsive, high-quality support to Portal’s engineering organization, balancing the speed engineers expect with the standards infrastructure and security require
  • Anticipate infrastructure needs ahead of demand, so engineering teams are rarely blocked waiting on IT

Security, Compliance & GRC Engineering

    • Build security and compliance into the design of every solution by default, in support of Portal’s CMMC Level 2, DFARS, and ITAR obligations
    • Apply GRC engineering practices: automate compliance evidence collection and control monitoring so the compliance program scales with the business rather than relying on manual review
    • Favor elegant, intuitive designs and living tooling (dashboards, monitoring, and infrastructure-as-code state) as the primary record of how systems work; keep written documentation lean and reserved for what truly needs it
    • Balance robust, right-sized solutions against cost, avoiding both under-engineering that creates risk and over-engineering that wastes budget

 

What you bring to Portal

  • Strong hands-on Azure expertise: comfortable designing with managed services, PaaS, containers, and other cloud-native patterns, not just running VMs in the cloud, and with enough VMware fluency to operate and modernize a simple, single-cluster on-premises environment
  • Strong command of Microsoft Entra ID and the broader Microsoft 365/Azure ecosystem: conditional access, identity governance, and tenant administration
  • Comfort designing and troubleshooting enterprise networking (routing, switching, firewalls, VPN); Fortinet experience is a plus
  • Hands-on backup and disaster recovery engineering experience, including tools like Veeam, treating DR as a continuously tested capability rather than a checkbox
  • Practical experience with infrastructure as code and configuration management (Terraform, Bicep, Ansible, or similar), and a cloud-first mindset that treats instances as cattle rather than pets
  • Comfort applying GRC engineering practices — automating compliance evidence, monitoring, and control tracking — rather than relying on manual, document-heavy compliance processes
  • A bias toward elegant, self-explanatory solutions: using code, automation, and live observability tooling as the primary way systems are understood, rather than documentation that goes stale as systems drift
  • Ability to operate as both architect and implementer: comfortable proposing a design and then spending the hours to build, configure, and debug it until it works
  • Strong customer-service orientation toward technically demanding internal engineers, combined with an instinct to solve recurring issues permanently through better design rather than repeated fixes
  • Comfort working in a compliance-sensitive, ITAR-controlled environment, and willingness to participate in an on-call rotation for critical infrastructure incidents


Basic Qualifications 

  • 5+ years of experience in infrastructure, systems, or network engineering, including hands-on administration of Microsoft Azure IaaS and PaaS services
  • 2+ years of experience administering VMware or comparable on-premises virtualization environments
  • 2+ years of experience with backup and disaster recovery engineering, including tools such as Veeam and cloud-based DR solutions
  • 2+ years of experience administering Microsoft Entra ID (Azure AD) and the Microsoft 365 stack, including identity management, conditional access, and tenant configuration
  • 2+ years of experience with enterprise networking, including firewalls, switching, routing, and VPN/remote access administration
  • 2+ years of experience acting as an escalation point or technical lead for engineers or a service desk on infrastructure issues
  • 1+ years of experience with infrastructure as code, scripting, or automation using tools such as PowerShell, Terraform, or Bicep

Preferred Qualifications

  • Microsoft Azure certification (AZ-104, AZ-305, or similar)
  • Experience modernizing or migrating legacy on-premises workloads to cloud-native architectures (containers, PaaS, serverless), rather than straight lift-and-shift
  • Veeam certification (VMCE) or demonstrated advanced Veeam backup/DR experience
  • Experience with Fortinet or comparable enterprise network/security platforms
  • Security certification (CompTIA Security+, ISC2 CC, or equivalent), or willingness to obtain within 6 months of hire
  • Experience with GRC automation or compliance tooling (e.g., Drata, Vanta, or similar) and/or exposure to CMMC, NIST 800-171, or FedRAMP frameworks
  • Familiarity with Microsoft 365 GCC High, Azure Government, or other FedRAMP-aligned environments
  • Experience partnering with or overseeing an MSP relationship for service desk, networking, or M365 support
  • Experience with logging/observability platforms (e.g., Azure Monitor, Sentinel, Graylog, Datadog or similar)
  • Experience in or genuine interest in aerospace or space technology

Work Expectations

  • Willingness to participate in an on-call rotation for critical infrastructure incidents

ITAR Statement

This position may involve access to technical data and defense-related materials controlled under the International Traffic in Arms Regulations (ITAR). Eligibility to access ITAR-controlled items requires that candidates be U.S. persons, which includes U.S. citizens, lawful permanent residents, and other protected individuals as defined by U.S. law. Employment is contingent upon verification of ITAR eligibility and, where applicable, obtaining any required export authorization or license.

 

Equal Opportunity Statement

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.